SSO and API gateway2023Backend engineer4 months

Identity Gateway

Single sign-on across a suite of enterprise apps with an OIDC gateway, short-lived tokens and centralised session revocation.

  • Spring Security
  • OAuth2 / OIDC
  • Redis
  • Kubernetes
5 to 1
logins per employee
<60s
global access revocation

The problem

Each application stored its own passwords. Off-boarding an employee meant touching five systems, and audits failed.

Constraints

Architecture

Key decisions

Decision 01
Short access tokens, server-side refresh

Access tokens live 5 minutes and refresh tokens never reach the browser, so revocation is a single Redis delete.

Trade-off: More refresh traffic through the gateway.

In the code

gateway/src/main/java/SecurityConfig.java
1@Bean2SecurityFilterChain api(HttpSecurity http) throws Exception {3  return http4      .authorizeHttpRequests(auth -> auth5          .requestMatchers("/actuator/health").permitAll()6          .anyRequest().authenticated())7      .oauth2ResourceServer(rs -> rs.jwt(jwt -> jwt8          .jwtAuthenticationConverter(new RoleConverter())))9      .sessionManagement(s -> s.sessionCreationPolicy(STATELESS))10      .build();11}

What I learned